Authenticated SQL Injection Vulnerability in OpenRemote by OpenRemote
CVE-2026-62238

7.2HIGH

Key Information:

Vendor

Openremote

Vendor
CVE Published:
17 July 2026

What is CVE-2026-62238?

OpenRemote versions prior to 1.26.0 are susceptible to an authenticated SQL injection vulnerability within the datapoint crosstab export functionality. By leveraging this flaw, an attacker with asset creation or renaming privileges can manipulate SQL queries through the asset name input. This injection can lead to unauthorized data exposure, allowing the attacker to extract sensitive information from the database via the resultant CSV export.

Affected Version(s)

openremote 0 < 1.26.0

openremote 1.26.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

aramosf
.